Live data from Hacker News

Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

bitcoinmagazine.com

61–70 of 76 posts

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#61

I'm not a crypto expert at all but I do have one question: If there is a concept of "quantum-safe" (which I did not know until reading this article), why hasn't the broader internet (HTTPS) adopted them? Is there any plans for there adoption in the future?

Block ciphers can be easily made quantum-safe by doubling the key size (see "Grover's Algorithm"). We might have to update everyone's browser to support extending AES to 512 bits, but it's doable.

The real problem is public key ciphers that rely on prime number factorization. Eliptic curves are one solution, but the only people who seem to have in-depth knowledge about them are in the NSA.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#62

I'm not a crypto expert at all but I do have one question: If there is a concept of "quantum-safe" (which I did not know until reading this article), why hasn't the broader internet (HTTPS) adopted them? Is there any plans for there adoption in the future?

The mathematics are less well researched, and at least for some algorithms the keys are quite large. (For instance, a pretty standard sized Niederreiter key and a single Niederreiter signature put the minimum size for a certificate over 1 MB, which is a lot less onerous than it used to be, but a bit big for doing a lot of copying on cellular networks.)

I haven't heard this expressed anywhere, but it could also be that the McEliece and Niederreiter algorithms have a bit of a feel to them like the Merkle-Hellman knapsack algorithm that was thought for a long time to be secure.

Though, if you're being paranoid and can spare the cycles, it wouldn't hurt to take Elliptic Curve Diffie-Hellman (or ECIES) exchange, encrypt that using RSA (or ElGamal), and then Encrypt that using Niederreiter (or McEliece), like a bunch of Russian dolls nested by key/message size. All three crypto systems would need to be broken in order to recover the key.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#63

my takeaway from this article just reinforces the perception of Bitcoin I already had, namely: which do I trust more? a monetary system run by engineers & mathematicians. or a monetary system run by politicians/lawyers, government bureaucrats, and an old-money banking aristocracy? Choices, choices...

I've worked with a lot of engineers. Most of us aren't really that smart and usually we make problems much more complicated than they need to be.

I'd trust a unique and fairly original monetary system run by good engineers. But most engineers are really not that good.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#64
post #47

> As a result, most of the decisions that Satoshi Nakamoto made in 2008 we are essentially stuck with. Every single time I read something about what 'Satoshi Nakamoto' did in designing, implementing and securing Bitcoin, I grow more skeptical that one person, or even a small group of people, created Bitcoin. It is very difficult to believe that something this sophisticated was developed by anyone other than a well fi…

Imagine if it really is just one individual hacker that got extremely lucky (both with Bitcoin's success & maintaining their secret identity)... What must that person be thinking right now?

probably wondering how long until the bitcoin economy is stable enough for him to spend any of his fortune without it immediately collapsing after all he is said to have a truly massive share of the bitcoins produced setting in his wallet.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#65
post #63

my takeaway from this article just reinforces the perception of Bitcoin I already had, namely: which do I trust more? a monetary system run by engineers & mathematicians. or a monetary system run by politicians/lawyers, government bureaucrats, and an old-money banking aristocracy? Choices, choices...

I've worked with a lot of engineers. Most of us aren't really that smart and usually we make problems much more complicated than they need to be. I'd trust a unique and fairly original monetary system run by good engineers. But most engineers are really not that good.

I've seen evidence that suggests the leading engineers behind Bitcoin are good. In contrast, I've seen repeated evidence over decades that the folks leading the US government are dangerously incompetent on things which are incredibly important to get right for all the rest of us, namely the economy, the environment/ecosystem and health care.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#66
post #51

Matthew Green and Paulo Barreto were making fun of this on Twitter. No, the use of a hash does not mean bitcoin will survive quantum cryptanalysis. As Green --- not a stranger to the workings of bitcoin --- puts it, "if the elliptic curve discrete log problem is solved, bitcoin is toast". Further, the "smart" curve choice bitcoin made was simply not using the NIST P-curves. But lots of stuff chose not to use the NIST…

The point in the article was that if you sent the coins to an address that never spent any coins (like the reference client does where it will always create a new "change" address for left over coins from a transaction) then the public key of the address that holds your coins will never be seen on the network.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#67
post #55
post #43

Earlier quoted context omitted.

Satoshi mined bitcoins alone for a long time, back when it was easiest. If they did not lose those original coins, they are stupidly rich. When you hit a jackpot like this, remaining silent and denying everything is one of the most sensible courses of action.

People are keeping a close eye on the addresses holding all of those bitcoins. I wonder how he'll avoid being detected when trying to withdraw them.

I guess when there are some more established exchange services they could slowly pull some of that money out in relatively good anonymity. (Assuming that a more established service would not sell their name to the press.)

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#68
post #51

Matthew Green and Paulo Barreto were making fun of this on Twitter. No, the use of a hash does not mean bitcoin will survive quantum cryptanalysis. As Green --- not a stranger to the workings of bitcoin --- puts it, "if the elliptic curve discrete log problem is solved, bitcoin is toast". Further, the "smart" curve choice bitcoin made was simply not using the NIST P-curves. But lots of stuff chose not to use the NIST…

For everyone who was also looking for the tweets: https://twitter.com/pbarreto/status/395378161631784960

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#69
post #32

Earlier quoted context omitted.

Honestly, "the NSA or some secret group with a PR agency created Bitcoin" sounds more like a conspiracy theory than "a lone programmer wanted to experiment with ideas of a peer-to-peer currency"... There are 2 simple reasons why Satoshi would want to remain anonymous: #1 He is estimated to own ~1 million BTC ($200 million); many thieves would capture/torture/murder someone for the chance to steal that amount! #2 Some…

#3 In his foot, I'd be paranoid against a governemnt declaring me some kind of enemy or terrorist.

That's a conspiracy theory.

Bitcoin will not be outlawed by the US or Europe. China seems like the only remaining threat as far as outlawing Bitcoin.

Re: Unexpected Ways in which Bitcoin Dodged Some Cryptographic Bullets

#70
post #44

Who created Bitcoin? This comment seems to offer many clues: https://news.ycombinator.com/item?id=5547590 There are two groups that are on the suspects list for having engendered bitcoin, one group centers around Trinity College, another is a bunch of loosely affiliated international collaborators. Both groups are on the record with precursors to bitcoin (papers, software), neither has admitted openly that they were…

I have a related question. Why hasn't the creator(s) come forward? What reason is there for hiding their identity? I'm starting to add more tin foil to my hat these days and this sort of thing worries me.

He wants to remain anonymous almost certainly because he is estimated to own ~1 million BTC ($200 million!); and a lot of thieves would track/kidnap/torture/murder someone for the chance to steal that amount.
Post reply on HN